BlockBriefe
Bitcoin

Blockstream Confirms Liquid Network Bridge Nodes Secured After $320 Million Exploit

Olivia Carter 07.09.2026

How the Exploit Occurred and the Response Taken

Blockstream announced on September 7 that the bridge nodes of its Liquid Network have been patched and secured following a major exploit that resulted in the theft of approximately 4,000 BTC, valued at around $320 million. The company stated that the vulnerability has been addressed and that conditions are now in place for the return of the stolen funds. Roughly 3,998.5 BTC remain in the exploiter’s wallet, and Blockstream is using PGP-signed Bitcoin messages to coordinate their restitution. The incident underscores ongoing security challenges in blockchain infrastructure, particularly around cross-chain bridges that facilitate asset transfers between networks.

The exploit targeted the Liquid Network’s bridge mechanism, which allows users to move Bitcoin between the main chain and the Liquid sidechain. Attackers took advantage of a flaw in the validation process of bridge nodes, enabling them to mint unauthorized assets and withdraw funds. Blockstream detected the anomaly and immediately halted operations to prevent further loss. Engineers worked to isolate the vulnerability, deploy patches across all bridge nodes, and enhance monitoring systems. The company emphasized that user funds on the Liquid Network were never at risk during the incident, as the breach was confined to the bridge’s operational layer. Coordination with exchanges and wallet providers helped trace the stolen BTC to a single wallet, which remains under observation.

What Steps Are Being Taken to Recover the Stolen Funds

Blockstream is leveraging cryptographic verification methods to communicate securely with the party controlling the exploiter’s wallet. By sending PGP-signed messages via Bitcoin transactions, the company aims to establish a verifiable channel for negotiation and fund return. This method ensures authenticity and prevents impersonation during recovery efforts. While no direct contact has been confirmed, Blockstream stated that the exploiter has not moved the funds since the attack, suggesting potential openness to dialogue. The firm reiterated that any return of funds would be voluntary and conducted in compliance with legal and ethical standards. No bounty or reward has been publicly offered, though Blockstream noted it is exploring all available avenues to resolve the situation.

Was the Liquid Network itself compromised during the exploit? No, the core Liquid Network protocol and user wallets remained secure. The vulnerability was isolated to the bridge nodes responsible for pegging Bitcoin in and out of the sidechain.

Frequently Asked Questions

Is there a timeline for when the stolen funds will be returned? Blockstream has not provided a specific timeline, as the return depends on cooperation from the exploiter. The company is actively pursuing communication channels to facilitate restitution.

Are users required to take any action to protect their funds? No, users do not need to take any action. Blockstream confirmed that all Liquid Network user funds were unaffected and remain secure.

Share:

More stories: